As in https://github.com/shieldfy/API-Security-Checklist/blob/master/README.md Some things should be verified in API implementations, such as https://github.com/JanitorTechnology/janitor/blob/master/api/